Files
hermes-agent/plugin-catalog/hindsight.yaml
happy5318 839fb764c2 fix(plugins): gate installs of catalog entries that document known issues (#124037)
## Thinking Path
`plugin-catalog/hindsight.yaml` already documented in prose that
`local_embedded` mode is unsupported on PM-managed Hermes with the current
pin — it still calls the retired lazy-install path for `hindsight-all` and
loops update takeover on every conversation — yet `hermes plugins install`
and the dashboard install path accepted the entry with no gate at all. Users
only discovered the trap after the death loop started. The catalog knew;
the installers didn't act on it.

## What Changed
- `hermes_cli/plugin_catalog.py`: new `known_issues: List[str]` field on
  `PluginCatalogEntry` (parsed from `known_issues` in each `plugin-catalog/*.yaml`,
  serialized into `to_dict()`, defaults to empty for backward compatibility).
- `plugin-catalog/hindsight.yaml`: declares the documented local-embedded trap
  as machine-readable `known_issues`.
- `hermes_cli/plugins_cmd_install.py`:
  - `cmd_install`: for catalog entries with `known_issues`, prints each issue
    and a bold-red notice, then requires explicit confirmation. Non-interactive
    (non-TTY) runs fail closed; interactive `y/N` runs require `y`.
  - `dashboard_install_plugin`: non-interactive path refuses the entry outright
    (no GUI bypass, mirroring the existing kill-list posture) and returns the
    issue list in the error payload.

## Why This Shape
The trap is machine-readable in the catalog, so the enforcement lives in the
install entry points rather than in hindsight-specific code — any future
catalog entry that documents a known trap gets the same gate for free. The
non-interactive path fails closed because it cannot ask for the confirmation
the interactive path requires.

## Verification
- RED/GREEN double proof via git stash: pre-fix 7 failed / 3 passed, post-fix
  10/10 passed (catalog parsing round-trip, hindsight.yaml declares the trap,
  non-TTY refuse, TTY yes proceeds, TTY no cancels, custom-source install not
  gated, dashboard refuse + unaffected path).
- Adjacent suites: test_plugin_catalog.py, test_plugin_validate.py,
  test_plugins_hub_live_catalog.py all green (36 passed). 9 errors in
  test_plugins_cmd_catalog.py reproduce identically with the fix stashed
  (existing local `pm` / uv-sync environment limitation, unrelated).
- ruff clean on all changed files.

## Contract Change
New optional catalog field `known_issues` (list of strings). Entries without
it behave exactly as before. Install behavior changes only for entries that
declare `known_issues`.

## Risks
- Catalog entries that declare `known_issues` become gated installs. Authors
  of future entries should only declare issues they want surfaced — this is
  the intended trade (a documented trap must not install silently).
- `cmd_install` non-TTY automation installing hindsight by name now fails.
  That is intentional: the trap cannot be confirmed non-interactively.

## Model Used
jd-deepseek-v4-flash-0731 (main session); pytest + ruff in the isolated
worktree.

## Related
#124037 (issue). Related: #122326 (resulting takeover loop), #7718
(`local_embedded` needs `hindsight-all`).
2026-09-27 17:06:55 -07:00

25 lines
1.3 KiB
YAML

name: hindsight
repo: https://github.com/vectorize-io/hindsight
sha: 176f8c2de1369f569c489b831d143b78128b5535
subdir: hindsight-integrations/hermes
version: "1.0.1"
description: Hindsight long-term memory provider — knowledge graph, entity resolution and multi-strategy
retrieval (recall/reflect/retain tools plus automatic per-turn capture). Maintained by Vectorize;
cloud and local external modes are available. Local embedded mode is not supported on PM-managed
Hermes with this plugin pin — it still calls the retired lazy-install path for `hindsight-all`.
`hermes memory setup` fetches its bank-template catalog from raw.githubusercontent.com
(vectorize-io/hindsight main).
maintainer: vectorize-io
tier: community
category: memory
requires_hermes: ">=0.21.4"
known_issues:
- "Local embedded mode is not supported on PM-managed Hermes with this plugin pin — it still calls the retired lazy-install path for `hindsight-all`, which loops update takeover on every conversation. On managed installs prefer `local_external` or cloud mode."
docs_url: https://hindsight.vectorize.io/sdks/integrations/hermes
image: https://raw.githubusercontent.com/vectorize-io/hindsight/176f8c2de1369f569c489b831d143b78128b5535/hindsight-integrations/hermes/docs/banner.png
capabilities:
provides_tools: []
provides_hooks: []
provides_middleware: []
requires_env: []